Privacy Policy

Menu Explain · Last updated 18 July 2026

Menu Explain is operated by Mentioned In, LLC, a Delaware limited liability company (“Menu Explain”, “we”). We are the data controller for the personal information described here. This policy explains what we collect when you use the Menu Explain mobile app (the “App”), why, and the choices you have. Contact: [email protected].

1. Information we collect

The App has no login and does not ask for your name, email, or account. We collect only:

CategoryWhat it is
Menu photos & extracted textThe menu images you capture and the text read from them, which we send for processing to produce translations, possible allergens, calorie estimates, and price conversions.
App-generated identifierA unique identifier (UUID) our App generates and stores on your device to run the service, keep track of your Scan Credits and day passes, and link your usage over time. This identifier is persistent and, under data-protection law, is treated as personal (pseudonymous) information — it is not anonymous.
Usage & device dataHow you interact with the App (screens viewed, features used), plus device type, operating-system version, app version, and language, collected through our analytics provider.
Purchase recordsRecords that you bought Scan Credits or a day pass. Payments are handled by Apple or Google; we do not receive your card details.
Messages you send usIf you email us for support, the content of that message.

We do not collect your location, we do not ask you to store any allergy or medical profile, and we do not use advertising or attribution SDKs in the App.

2. How your menu photos are processed

When you scan a menu, the image and the text read from it are sent to our hosting and database infrastructure, provided by DigitalOcean and Supabase, and to OpenAI, whose AI models generate the translation, possible-allergen flags, calorie estimates, and price conversions. Under OpenAI’s API terms, data sent through the API is not used to train their models and is retained by them only briefly for abuse monitoring. We store the menu photos and their extracted text on our own infrastructure so they appear in your in-app scan history (“Past Scans”). We keep them until you delete the scan, delete your data, or remove the App, and you can ask us to delete them at any time (see Section 8).

3. Why we use your information, and our legal bases

We use the information above to operate the App (read and translate menus and produce allergen, calorie, and price outputs), to keep track of your credits and passes, to fix problems and improve reliability and accuracy, to process purchases, to respond to support requests, and to comply with law and protect our rights.

For users in the EEA and UK, our legal bases under the GDPR/UK GDPR are:

  • Contract — to deliver the scans and features you request and manage your credits;
  • Legitimate interests — to keep the App secure, working, and improving, balanced against your rights;
  • Consent — for usage analytics, which we activate only where you have agreed, and which you can withdraw at any time in the App’s settings;
  • Legal obligation — where the law requires us to retain or disclose information.

4. Who receives your information

  • OpenAI — processes menu images and text to generate the App’s outputs.
  • DigitalOcean (United Kingdom) — hosts our backend server, which runs the App’s business logic but does not store your data.
  • Supabase / Amazon Web Services (United States, US East) — our database and storage, where menu photos, extracted text, and app data are kept.
  • Mixpanel — our analytics provider, which receives usage and device data and your app-generated identifier to help us understand and improve how the App is used.
  • Apple and Google — for app distribution and to process in-app purchases, under their own privacy policies.
  • Legal and safety — authorities or advisers where required by law or to protect rights and safety.
  • A successor — if the business is sold or reorganized.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

5. International data transfers

Our backend server, which runs the App’s business logic without storing your data, is located in the United Kingdom (London). All stored data — menu photos, extracted text, and app data — is held with Supabase on Amazon Web Services in the United States (US East), and OpenAI and Mixpanel also process data in the United States. For users in the EEA, transfers to the United Kingdom are covered by the European Commission’s UK adequacy decision; transfers to the United States (for storage, AI processing, and analytics) rely on the European Commission’s Standard Contractual Clauses, and for UK users the UK International Data Transfer Addendum, or another lawful mechanism such as the EU–US Data Privacy Framework where the provider is certified. You can request details using the contact below.

6. How long we keep information

We keep your menu photos and their extracted text to power your in-app scan history, and retain them until you delete the scan, delete your data, or remove the App. We retain usage and analytics data and your app-generated identifier for 24 months. Your Scan Credits and day passes are held on your device against your app-generated identifier for as long as the App is installed. You can ask us to delete your scan history (including the stored menu photos) or all of your data at any time by contacting us (see Section 8).

7. Allergy and health information

The App flags possible allergens in menu dishes as a general convenience, but it does not ask you to create or store a personal allergy or medical profile, and we do not collect special-category (health) data about you. Allergen flags are estimates only — always confirm with the restaurant, as explained in our Terms of Service.

8. Your rights

8.1 EEA and UK users

You have the right to access, correct, delete, restrict, or object to our processing of your personal information, to data portability, and to withdraw consent at any time. You also have the right to complain to your local data protection authority. Because we identify you only by your app-generated identifier, please include it when you make a request — you can find and copy it on the accounts page in the App. Email [email protected].

8.2 California users (CCPA/CPRA)

California residents may request to know, access, correct, and delete their personal information, and to opt out of any sale or sharing of it. We do not sell or share personal information as those terms are defined, and we will not discriminate against you for exercising your rights. To make a request, email [email protected].

8.3 Everyone else

Wherever you live, you can contact us to access or delete your information and we will respond as required by applicable law.

9. Children

The App is not intended for children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.

10. Security

We use reasonable technical and organizational measures, including encrypted connections, to protect personal information. No system is perfectly secure and we cannot guarantee absolute security.

11. Changes to this policy

We may update this policy from time to time. We will change the date above and, for material changes, provide notice in the App where required.

This policy is governed by the laws of the State of Delaware, United States, without limiting any mandatory data-protection rights you have under the laws of your country of residence.

12. Contact us

Mentioned In, LLC 1111B S Governors Ave STE 23908, Dover, DE 19904, USA [email protected]